Business Associate Agreement
1. Definitions
Unless otherwise defined herein, terms have the meanings ascribed in 45 CFR §160.103 and the HIPAA Regulations, including:
- “HIPAA Regulations” means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Parts 160 and 164.
- “Protected Health Information” or “PHI” has the meaning given in 45 CFR §160.103, limited to PHI created, received, maintained, or transmitted by Business Associate on behalf of Covered Entity.
- “Electronic PHI” or “ePHI” means PHI that is transmitted or maintained in electronic media as defined in 45 CFR §160.103.
- “Covered Entity” means the health plan, health care clearinghouse, or health care provider that is a covered entity as defined in 45 CFR §160.103.
- “Business Associate” means TailoredGRC in its capacity as a business associate to Covered Entity, as defined in 45 CFR §160.103.
2. Obligations of Business Associate
Business Associate agrees to the following:
- Use and disclosure limitations. Use or disclose PHI only as permitted or required by this BAA, the Agreement, or as Required By Law, and not in a manner that would violate Subpart E of 45 CFR Part 164 if done by Covered Entity (except for uses and disclosures that are permitted for data aggregation or management and administration under 45 CFR §164.504(e)(4)).
- Safeguards. Implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI that it creates, receives, maintains, or transmits on behalf of Covered Entity, consistent with 45 CFR Part 164 Subpart C and Section 5 of this BAA.
- Subcontractors. Ensure that any subcontractors that create, receive, maintain, or transmit PHI on behalf of Business Associate agree in writing to substantially the same restrictions and conditions that apply to Business Associate under this BAA with respect to such PHI.
- Mitigation. Mitigate, to the extent practicable, any harmful effect of a use or disclosure of PHI by Business Associate or its subcontractors in violation of the requirements of this BAA.
- Reporting. Report to Covered Entity any use or disclosure of PHI not provided for by this BAA of which Business Associate becomes aware, including breaches of unsecured PHI as required under Section 6.
- Access and amendment. In accordance with 45 CFR §164.524 and §164.526, as applicable, accommodate reasonable requests by Covered Entity to access and amend PHI maintained by Business Associate in a Designated Record Set.
- Accounting. Document disclosures of PHI and make available to Covered Entity information required for Covered Entity to make available an accounting of disclosures in accordance with 45 CFR §164.528.
- HHS compliance. Make internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining Covered Entity’s compliance with the HIPAA Regulations.
3. Permitted Uses and Disclosures
Business Associate may use and disclose PHI to perform functions, activities, or services for, or on behalf of, Covered Entity as specified in the Agreement, provided that such use or disclosure would not violate the Privacy Rule if done by Covered Entity (or is otherwise permitted under the HIPAA Regulations for business associates).
Business Associate may use PHI for the proper management and administration of Business Associate or to carry out its legal responsibilities, and may disclose PHI for such purposes if the disclosure is Required By Law or if Business Associate obtains reasonable assurances from the recipient that the PHI will remain confidential and be used or further disclosed only as Required By Law or for the purpose for which it was disclosed, and the recipient notifies Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.
Business Associate may de-identify PHI in accordance with 45 CFR §164.514(b) in connection with providing the Services, where permitted under the Agreement.
4. Obligations of Covered Entity
Covered Entity agrees to:
- Notify Business Associate of any limitation(s) in its notice of privacy practices in accordance with 45 CFR §164.520, to the extent that such limitation may affect Business Associate’s use or disclosure of PHI.
- Notify Business Associate of any changes in, or revocation of, permission by an individual to use or disclose PHI, to the extent that such changes may affect Business Associate’s permitted uses or disclosures.
- Notify Business Associate of any restriction on the use or disclosure of PHI that Covered Entity has agreed to or is required to abide by under 45 CFR §164.522, to the extent that such restriction may affect Business Associate’s use or disclosure of PHI.
- Not request Business Associate to use or disclose PHI in any manner that would not be permissible under Subpart E of 45 CFR Part 164 if done by Covered Entity (unless permitted for data aggregation or management and administration as described in the HIPAA Regulations).
- Obtain any authorizations, consents, or permissions required for Business Associate to perform the Services, where applicable.
5. Security Requirements
Business Associate will implement safeguards appropriate to the size, complexity, and nature of the Services and the volume and sensitivity of ePHI, consistent with the requirements of the HIPAA Security Rule (45 CFR Part 164 Subpart C), including administrative safeguards (security management process, workforce security, information access management, security awareness and training, contingency plan, evaluation, and business associate contracts), physical safeguards (facility access controls, workstation use, device and media controls), and technical safeguards (access control, audit controls, integrity, person or entity authentication, and transmission security).
Covered Entity is responsible for configuring access credentials, assigning roles, and managing end-user devices and networks outside Business Associate’s control in accordance with Covered Entity’s policies and applicable law.
6. Breach Notification
Upon discovery of a breach of unsecured PHI as defined in 45 CFR §164.402, Business Associate will notify Covered Entity without unreasonable delay and in no case later than sixty (60) calendar days after discovery, in accordance with 45 CFR §164.410. The notification will include, to the extent known, the identification of each individual whose unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed as a result of the breach, and such other content as required by 45 CFR §164.410(c).
Covered Entity remains responsible for notifying affected individuals, the Secretary, and, where applicable, the media, in accordance with 45 CFR §164.404–§164.408.
7. Term and Termination
This BAA becomes effective on the Effective Date and continues until terminated as set forth herein or in the Agreement.
Either party may terminate this BAA and the underlying Agreement as permitted by the Agreement. Upon Covered Entity’s knowledge of a material breach by Business Associate, Covered Entity may provide an opportunity for Business Associate to cure the breach, and may terminate this BAA and the Agreement if cure is not feasible or is not timely accomplished, as permitted under 45 CFR §164.504(e)(2)(iii).
8. Return or Destruction of PHI upon Termination
Upon termination of this BAA for any reason, Business Associate will, at the option of Covered Entity, return or destroy all PHI maintained by Business Associate in any form and retain no copies of such information, or, if return or destruction is infeasible, extend the protections of this BAA to such PHI and limit further uses and disclosures to those purposes that make the return or destruction infeasible, in accordance with 45 CFR §164.504(e)(2)(ii).
Business Associate will document disposal or return in a manner consistent with its policies and applicable law.
9. Miscellaneous
Amendment
This BAA may be amended only in a writing signed by both parties, except that Business Associate may update non-material administrative provisions in posted templates when required to align with changes in law, with reasonable notice to Covered Entity.
Waiver
No waiver of any provision of this BAA will be effective unless in writing. Failure to enforce any provision is not a waiver of future enforcement.
Governing Law
This BAA is governed by the laws of the State of Missouri, without regard to conflict-of-law principles, except to the extent superseded by federal law.
Interpretation
Any ambiguity in this BAA will be resolved to permit Covered Entity and Business Associate to comply with the HIPAA Regulations.
10. Signatures
By signing below, the parties agree to be bound by this BAA as of the Effective Date.
Covered Entity
[Customer Company Name]
Signature
Print name & title
Date
Business Associate
TailoredGRC
Signature
Print name & title
Date
Questions regarding this BAA: btaylor@tailoredgrc.com